The Five Maturity Levels
Every organization fits somewhere on this curve. The goal isn't perfection — it's knowing your position and taking the next step.
Ad Hoc
1.0 – 1.9No formal AI security program. Tools are used ad hoc with no visibility, policy, or monitoring. Risk is unmanaged.
Aware
2.0 – 2.9Basic awareness exists. Some informal guidelines documented. Enforcement is manual and inconsistent. Gaps are widespread.
Managed
3.0 – 3.9Formal AI security policy in place. Basic monitoring and tool inventory exist. Automated detection is partial. Compliance mapping has begun.
Proactive
4.0 – 4.9Automated redaction and inspection in production. Audit trails are tamper-evident. Compliance evidence packages are exportable. Security is embedded into developer workflows.
Optimized
5.0Continuous improvement culture. AI security metrics are tracked and reviewed. Incident response is practiced. The organization leads its industry in AI security posture.
Ready to move up the maturity curve?
Shield runs locally on your machine — one env var, immediate redaction, and a tamper-evident audit trail. Know what leaves your network before the models do.